Back to skill

Security audit

架构图生成

Security checks across malware telemetry and agentic risk

Overview

This skill is a local diagram-generation helper with clear limits and no evidence of hidden network, credential, persistence, or destructive behavior.

Install only if you want a diagramming skill that may activate on broad diagram-related phrases. Review generated diagrams before sharing them, especially when you provide local architecture files, because the skill may summarize user-specified project details into HTML, SVG, or Mermaid output.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
86% confidence
Finding
The trigger scope is very broad, matching generic phrases like '画个图', 'system diagram', or 'architecture', which can cause the skill to activate in contexts where the user did not intend to invoke a diagramming tool. In an agent setting, over-broad activation can misroute requests, override more appropriate skills, or cause unintended file generation and handling of sensitive architectural content.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger description includes broad, everyday phrases such as '画个图' and generic English words like 'draw/diagram/flowchart/architecture', which can cause the skill to activate in contexts far beyond its intended scope. Over-broad activation increases the chance that unrelated user requests are intercepted, leading to unsafe context switching, incorrect tool use, or accidental processing of sensitive local files if the workflow later asks to read user-specified paths.

VirusTotal

56/56 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.